cve/2022/CVE-2022-43701.md

18 lines
1.1 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-43701](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43701)
![](https://img.shields.io/static/v1?label=Product&message=Arm%20Compiler%205%20(AC5)%2C%20Arm%20Compiler%20for%20Embedded%206%20(AC6)%2C%20Fast%20Models%20(FM)%2C%20Arm%20Compiler%20for%20Embedded%20FuSA%20(ACEF)%2C%20Arm%20Development%20Studio%20(ADS)%2C%20Arm%20Forge%20(AF)%2C%20Arm%20Mobile%20Studio%20(AMS)%2C%20DS-5%20Development%20Studio%2C%20Fast%20Models%20(FM)%2C%20GNU%20Toolchain%20(GT)%2C%20Keil%20MDK%20(KMDK)%2C%20Mbed%20Studio%20(MS)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-276%20Incorrect%20Default%20Permissions&color=brighgreen)
### Description
When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.
### POC
#### Reference
- https://developer.arm.com/documentation/ka005596/latest
#### Github
No PoCs found on GitHub currently.